Security incident · 2024-04-19
Hedgey
According to the public DefiLlama incident dataset, Hedgey (Arbitrum, Ethereum) suffered a security incident on 2024-04-19, with about $44.7M reported lost.
| Date | 2024-04-19 |
|---|---|
| Reported loss | $44.7M |
| Chain | Arbitrum, Ethereum |
| Target type | DeFi Protocol |
| Technique class | Input Validation |
| Technique | Missing Input Validation |
| Bridge incident | No |
| Within 2024 | #7 by loss that year, 2.7% of all reported losses that year |
How this kind of attack works
The contract did not check the parameters it received, and the attacker passed crafted data that made it do something it should not.
Would a pre-payment check have helped
Missing input validation is a contract code defect for code audits.
Other incidents with the same technique
- Portal2022-02-02 · $326.0M
- Orbit Bridge2023-12-31 · $81.7M
- Qubit2022-01-28 · $80.0M
- Cashio2022-03-23 · $52.8M
- Transit Swap2022-10-02 · $28.9M
- ThalaSwap2024-11-15 · $25.5M

